ThreatFox IOC Database
You are viewing the ThreatFox database entry for domain auth-confirm-two.vercel.app.
Database Entry
| IOC ID: | 1956248 |
|---|---|
| IOC: | auth-confirm-two.vercel.app |
| IOC Type : | domain |
| Threat Type : | payload_delivery |
| Malware: | ContagiousDrop |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS16509 AMAZON-02 |
| Country: | US |
| First seen: | 2026-10-07 10:38:28 UTC |
| Last seen: | never |
| UUID: | 89ff24ec-c238-11f1-bd13-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Reference: | https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/ |
Dethanc
Second-stage domains for Contagious Interview attack - interviewee is asked to clone repo that contains tasks.json, which auto-runs code in VSCode. This code harvests local credentials and sends them to malicious domains, which then respond with additional code to be executed on the compromised machine.A second payload in these repos triggers when the application is started, at which point these domains are called to carry out a similar procedure.
US